devops-kung-fu / bomber

Scans Software Bill of Materials (SBOMs) for security vulnerabilities
https://devops-kung-fu.github.io/bomber/
Mozilla Public License 2.0
516 stars 45 forks source link

VS Code extension #180

Open nhopkins19 opened 1 year ago

nhopkins19 commented 1 year ago

Create a VS Code extension, potentially integrated with Co-Pilot, for Bomber. Maybe we can somehow package Bomber with Syft or CycloneDX, and then working together with AI, have Bomber help facilitate the creation of a SBOM,etc

nhopkins19 commented 1 year ago

I wonder how or if we need to incorporate this latest CVSS update: https://www.first.org/cvss/v4-0/